|
307271
|
5.3 |
MEDIUM
Network
|
givewp
|
givewp
|
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.15.1. This is due to the plugin utilizing Symf…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2024-6551
|
2024-10-5 00:57 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307272
|
4.7 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Avoid race between dcn35_set_drr() and dc_state_destruct()
dc_state_destruct() nulls the resource context of the…
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-46850
|
2024-10-5 00:30 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307273
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
perf/x86/intel: Limit the period on Haswell
Running the ltp test cve-2015-3290 concurrently reports the following
warnings.
perf…
|
NVD-CWE-noinfo
|
CVE-2024-46848
|
2024-10-5 00:23 |
2024-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307274
|
7.5 |
HIGH
Network
|
planet
|
gs-4210-24p2s_firmware gs-4210-24pl4c_firmware
|
The swctrl service is used to detect and remotely manage PLANET Technology devices. Certain switch models have a Denial-of-Service vulnerability in the swctrl service, allowing unauthenticated remote…
|
CWE-476 CWE-400
NULL Pointer Dereference Uncontrolled Resource Consumption
|
CVE-2024-8454
|
2024-10-5 00:11 |
2024-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307275
|
4.9 |
MEDIUM
Network
|
planet
|
gs-4210-24p2s_firmware gs-4210-24pl4c_firmware
|
Certain switch models from PLANET Technology use an insecure hashing function to hash user passwords without being salted. Remote attackers with administrator privileges can read configuration files …
|
CWE-328 CWE-759
Use of Weak Hash Use of a One-Way Hash without a Salt
|
CVE-2024-8453
|
2024-10-5 00:10 |
2024-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307276
|
7.5 |
HIGH
Network
|
planet
|
gs-4210-24p2s_firmware gs-4210-24pl4c_firmware
|
Certain switch models from PLANET Technology only support obsolete algorithms for authentication protocol and encryption protocol in the SNMPv3 service, allowing attackers to obtain plaintext SNMPv3 …
|
CWE-327 CWE-328
Use of a Broken or Risky Cryptographic Algorithm Use of Weak Hash
|
CVE-2024-8452
|
2024-10-5 00:10 |
2024-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307277
|
7.5 |
HIGH
Network
|
planet
|
gs-4210-24p2s_firmware gs-4210-24pl4c_firmware
|
Certain switch models from PLANET Technology have an SSH service that improperly handles insufficiently authenticated connection requests, allowing unauthorized remote attackers to exploit this weakn…
|
CWE-400 CWE-280
Uncontrolled Resource Consumption Improper Handling of Insufficient Permissions or Privileges
|
CVE-2024-8451
|
2024-10-5 00:09 |
2024-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307278
|
9.8 |
CRITICAL
Network
|
planet
|
gs-4210-24p2s_firmware gs-4210-24pl4c_firmware
|
Certain switch models from PLANET Technology have a Hard-coded community string in the SNMPv1 service, allowing unauthorized remote attackers to use this community string to access the SNMPv1 service…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2024-8450
|
2024-10-5 00:08 |
2024-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307279
|
6.8 |
MEDIUM
Physics
|
planet
|
gs-4210-24p2s_firmware gs-4210-24pl4c_firmware
|
Certain switch models from PLANET Technology have a Hard-coded Credential in the password recovering functionality, allowing an unauthenticated attacker to connect to the device via the serial consol…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2024-8449
|
2024-10-5 00:08 |
2024-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307280
|
8.8 |
HIGH
Network
|
planet
|
gs-4210-24p2s_firmware gs-4210-24pl4c_firmware
|
Certain switch models from PLANET Technology have a hard-coded credential in the specific command-line interface, allowing remote attackers with regular privilege to log in with this credential and o…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2024-8448
|
2024-10-5 00:07 |
2024-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|